08-05-2019 07:34 AM - last edited on 08-05-2019 12:57 PM by John Vintzel
08-05-2019 07:34 AM - last edited on 08-05-2019 12:57 PM by John Vintzel
Hello Team, The cert that we planning to use would be valid for 2 years. What will happen after it expires? Do we need to ignore the expiry dates of the certificates while injecting into the package during its creation?
08-05-2019 12:59 PM
Solution@Prashant_Patale I moved this item to a conversation as well so other can follow along.
We highly recommend time stamping the app when signing. If you use time stamping the apps will continue to deploy after the cert expires, without it you will need to resign you package.
More information here: https://docs.microsoft.com/en-us/windows/msix/package/signing-package-overview
John Vintzel (@jvintzel)
PM Lead, MSIX
08-13-2019 06:39 AM
@John Vintzel Thank you for the details John. This is really helpful.
05-07-2020 09:16 AM - edited 05-07-2020 09:17 AM
@John Vintzel we have a customer that would like to outsource the packaging of apps with MSIX to a provider. They plan to offer a certificate - which will be used by the provide to sign packages - and they have asked what happens when they revoke that certificate , will installations initiated after the revocation date still work? Is this process influenced by TSA aswell?
05-07-2020 04:19 PM
Hi @WesleeJKN0487,
If a certificate is revoked, previous installations and any future attempts will no longer be trusted. The timestamp does not matter if the certificate is revoked, only if the certificate expires.
Best,
Sharla
05-08-2020 12:18 AM